About time. We need open and verifiable firmware, at the very least, to be able to trust anything. Now if only they'd turn this lens on American-made devices which are likewise opaque, insecure, and likely to be weaponized against us as soon as security updates stop....
> We need open and verifiable firmware, at the very least, to be able to trust anything. How? Even ignoring ASICs, I just don't see how it's possible. Even if you had no binary blobs anywhere (we are already in the wonderland), with process for turning source to binary, you need to trust compiler, cpu, flashing hardware and software and the whole lot of other things. And that's all ignoring the fact that hiding bad s…
I think we do, but the implications of it are terrifying, overwhelming and just make people shrug and say "That'll never happen".
How I see it there are two sides.
Those who want a functioning technological society with all the benefits we believe in as hackers - transport, medicine, communications, planning... For that we'll have no choice but to make computers secure.
That side is "society".
In the other corner are those who do not want computers to be secure (despite what they say). They benefit from insecurity. These are;
- Criminals.
- Governments.
- Industry.
They are not aligned and fight amongst themselves. Only the criminals
are honest in that they don't pretend to want secure computing.
Governments and industry want secure computing for themselves, but not
for the others, or for society.For secure computing to ever happen three well organised, well funded and determined groups would have to lose against a disorganised, distributed, and poor remainder.
There are two things on our side to give us hope;
- That the enemy of my enemy is a temporary friend.
- Mathematics.